DRAFT — not legal advice. This was generated from the app’s actual data practices as a starting point and has not been reviewed by an attorney. Review and finalize it with counsel before relying on it. Bracketed items like [LEGAL ENTITY] are placeholders to fill in.

Privacy Policy

Last updated: [EFFECTIVE DATE]

This policy explains what StayLane (“we,” “us”) collects, why, who else sees it, how long we keep it, and what you can ask us to do with it. StayLane is run by [LEGAL ENTITY — e.g., StayLane, Inc.].

1. The short version

StayLane helps couples and event hosts set up a hotel room block — a set of rooms held at a group rate for your guests — with hotel sales teams. To do that we collect the details you give us about your event and how to reach you. The hotels you choose get your event details so they can quote. A small set of service providers run the product for us, and one AI provider helps our team read hotel replies and write the hotel descriptions you see. We do not sell personal data and we do not use it for advertising. You can ask us to see, correct, or delete your data at any time by emailing hello@staylaneblocks.com.

2. Who this policy covers

  • Couples and hosts — the person planning the event, from the first form answer onward, with or without an account.
  • Hotel staff — sales reps and other hotel contacts who receive requests and respond to them.
  • Site visitors — anyone browsing the site or using the room calculator.

It does not cover your guests or attendees. They book their rooms directly with the hotel, off StayLane, and we never collect their names or details. The only guest information we hold is the headcount you give us.

3. What we collect

What we collect depends on who you are.

Couples and hosts:

  • Contact and account details — name, email, phone, and a password if you set one. If you sign in with Google, Google gives us your name and email.
  • Event details — event type and name, dates, venue and city, guest count and how many guests are from out of town, the number of rooms you want, your budget range, hotel style preferences, and anything you type in the notes (special requests, hotels you have already contacted).
  • Contract details — when you accept a quote: your legal name, mailing address, phone, and email, so the hotel can draft the contract.
  • Messages — revision requests and answers to hotel questions you write on StayLane.

Hotel staff:

  • Contact details — name, work email, phone, role, and notes. Some of this you give us; some our team enters after a call with your property so we can send you requests.
  • Quotes and paperwork — the terms you quote, the text of any emailed reply our team pastes in, your contract templates, draft and signed contracts you upload, and the signer name and email on a contract.
  • Access applications — your name, role, hotel name and address, and notes.
  • Call notes — when our team calls you, we record the outcome and notes.

Everyone:

  • Technical data — your IP address (used to limit abuse and kept 7 days), timestamps, which steps of the intake form and the quote comparison you use, and error reports when something breaks. Our usage analytics record steps and field names, never names, emails, or what you typed.
  • Email records — a copy of every email we send, with its delivery status (delivered, bounced, marked as spam). Open and click tracking is turned off.

4. Where it comes from

  • From you — on the intake form, at sign-up, in your dashboard or hotel portal, and in emails you send us.
  • From the other side of your deal — hotels enter quotes and contract terms; hosts enter the event details a hotel sees in a request.
  • From our team — hotel contacts entered after a call with the property, call notes, and quotes our team enters when a hotel replies by phone or email instead of in the portal.
  • From Google — hotel listings (name, address, photos, ratings, reviews) and, if you sign in with Google, your name and email.
  • Automatically — technical data as you use the site.

5. How we use it

  • Run the service — estimate how many rooms to ask for, match you with hotels, send your request to the hotels you pick, relay quotes, questions, and revision requests between you and the hotel, and pre-fill contract documents.
  • Send the emails the service needs — confirmations, new quotes, hotel questions, reminders, contract updates, and sign-in links and codes. We don’t send hosts marketing email — every email you get is about a request you started. Hotels may receive requests and invitations from us on a host’s behalf; see section 10 for how to stop them.
  • Keep a person in the loop — every completed request and every deal milestone sends an alert to our team (event name, city, headcount, and your email) so someone can step in when the automation can’t.
  • Keep it working and safe — debugging, rate limiting, and abuse prevention.
  • See how the product is used — first-party analytics of the steps people take, never the values they type.
  • Keep business records and meet legal obligations — for example, the record of a signed block and any open business between the hotel and StayLane.

We do not sell personal data, and we do not use it for advertising.

6. What hotels see

When you send a request, each hotel you picked gets an email with your event name, event type, venue, city and state, stay dates, guest count, the rooms you are asking for by night, and — if you gave them — the kind of block you want and the date you plan to decide by. It also includes any special requests you typed and whether you told us your dates are flexible. Your event name may include your names. The request does not include your email, phone, or budget — the hotel quotes against its own rates, not your ceiling. Hotels reply through their StayLane portal, so your contact details stay with us until you accept.

When you accept a quote, each hotel whose quote you accept receives your legal name, mailing address, phone, and email so it can draft the contract. We also relay, word for word, any revision request or answer you write to that hotel, and any question the hotel asks you.

Hotel staff: the host sees your quote and its terms and, once they accept, the name, role, email, and phone of your hotel’s primary contact, so they know who the contract will come from. The host never sees your hotel’s commercial terms with StayLane.

7. Signing in, cookies, and browser storage

Couples and hosts can sign in with a Google account, an emailed sign-in link or one-time code, or an email and password. Hotel staff sign in with an emailed link or a password, or through a request link or invite we emailed them. Sign-in links and codes work once and expire after 15 minutes; hotel request and invite links expire after 30 days and can be revoked.

Cookies: we set only the cookies needed to keep you signed in. There are no advertising, analytics, or tracking cookies, so you won’t see a cookie banner.

Browser storage: your browser keeps a draft of your intake form so you can come back to it, plus small working details like which hotels you selected and a random session ID for our usage analytics, and, until you sign in, a one-time key that lets this browser reopen and claim your event. Don’t share a device before you’ve signed in. None of it identifies you to anyone else, and clearing your site data removes it.

8. AI

We use one AI provider, Anthropic, for a few behind-the-scenes jobs. We don’t use AI to process your intake form, your hotel matches, or your room estimate — those are plain rules we run ourselves. The AI never reads your intake form as a whole; the one time it sees a few of your intake answers is below.

  • Reading hotel replies. When a hotel replies by email instead of in its portal, our team pastes the reply in and the AI turns it into a draft quote that a person checks before you see it. That reply is sent to Anthropic together with a few facts from your request so the terms can be checked against the ask: the event name (which may include your names), event type, stay dates, room count, and your budget range — and nothing else of yours.
  • Describing hotels. The AI writes short summaries and amenity lists from a hotel’s public Google listing, summarizes Google review snippets (reviewer names are left out), and estimates a typical nightly rate range. You never see an AI rate as a dollar figure — only a real quote or a price tier.

Anthropic processes this data for us under its own retention rules [ANTHROPIC RETENTION — confirm the account’s retention setting before stating a period]. AI output is a draft. A person checks parsed quotes, and you should always read the hotel’s actual terms before you accept or sign.

9. Who else handles your data

These companies run parts of the product for us. Each one gets only what its job needs and may use it only to provide that service to us.

  • Supabase — our database, sign-in system, and file storage. Everything we store lives here, including contract files.
  • Railway — hosts the application. Its logs can include error messages, which occasionally contain an email address.
  • Resend — sends every email we send, so it sees the recipient address and message content, and reports deliveries and bounces back to us. A sent email cannot be recalled from a recipient’s inbox.
  • Cloudflare — runs our domain and routes inbound mail. Replies to hello@staylaneblocks.com are forwarded to a Google Gmail inbox our team reads, so anything you email us is stored in Gmail.
  • Google — in three ways. If you choose Google sign-in, Google shares your name and email with us. We look up cities, venues, and hotels through Google Places (we send the text you typed, never your name or email) and show Google photos, ratings, and review snippets, including reviewers’ public display names, on hotel pages. Hotel photos load into your browser straight from Google’s servers, so Google sees your IP address when you view a hotel page.
  • Anthropic — the AI provider described in section 8.
  • GlitchTip — hosted error monitoring. When something breaks we get the error and the page it came from; no screen recordings or performance tracking. An error message can occasionally include an identifier such as an email address.
  • GitHub — runs our scheduled jobs (reminders, expiries, email sending). It sees job summaries, not your details.

We may also share data if the law requires it, to enforce our terms, to protect people or the service, or as part of a merger, acquisition, or sale of the business. [DPA STATUS — confirm data-processing agreements with each provider.]

10. Email and unsubscribing

Couples and hosts: every email we send you is about a request you started — confirmations, quotes, hotel questions, reminders, contract updates, and sign-in links — so there is no unsubscribe link and we send no marketing email. If you no longer want them, cancel your event from your dashboard or ask us to delete your account.

Hotel staff: request emails go to every contact on file at your property, including contacts our team entered after a call. Every outreach email has a “stop receiving room-block requests” link at the bottom. Using it stops new requests for your whole property; emails about a request already in progress may continue until it closes. Our team can turn requests back on if you ask. In your portal settings you can also turn off reminder emails and the post-event numbers request without stopping new requests.

11. How long we keep it

We keep your data until you ask us to delete it. We do not have automatic deletion schedules yet, with one exception: IP addresses used for rate limiting are deleted after 7 days. Sign-in codes and hotel request links expire on the schedule in section 7. Before risky maintenance we sometimes take a full backup of the database, kept on an operator-controlled device and deleted when no longer needed [BACKUP RETENTION — set a maximum]; deleting your account does not reach a backup taken before your request. [RETENTION SCHEDULE — decide whether to add one, e.g. events older than X months after the event date.]

12. Your choices: access, correction, deletion

You can update your name, phone, contact details, and password in your settings. For anything else, email hello@staylaneblocks.com. We will check that it’s you and respond within [RESPONSE WINDOW — e.g. 30 days; confirm with counsel]. We won’t treat you differently for asking.

Access and export: we will send you a copy of the data we hold about you. This is done by hand; there is no download button yet. [DATA COPY — confirm we want to promise a copy and who produces it.]

Deletion: there is no delete button in the app yet. Email us and a member of our team runs the deletion. Here is exactly what it does:

  • Deleted: your login, your profile, your contract files, and every email we sent you. Any event still in progress is cancelled and its hotel links are turned off.
  • Scrubbed: your name, email, phone, address, notes, and messages are removed from your event, request, and contract records.
  • Kept, without your details: the business record that an event existed — dates, city, room counts, budget band, the hotels’ quotes, and whether a block was signed. We keep these because our audit trail and any open business between the hotel and StayLane depend on them.
  • One exception: if you have a signed block with open business between the hotel and StayLane, we close that out first, then delete.

We also keep a one-line record that we processed your request. It includes the email address you asked from, so we can show the request was honored.

What deletion can’t reach: emails already delivered to hotels, the hotel’s own copy of your contract and contact details, replies you sent that sit in our Gmail inbox, copies held by our providers under their own retention rules, and backups taken before your request. Where a provider supports it, we pass your deletion request along.

Hotel staff: you can edit your contact details in your portal. To remove a login or your contact record, email us. [HOTEL DELETION — no rep-side erasure routine exists yet; confirm what we promise and the turnaround.]

[UNCLAIMED EVENT DELETION — no routine exists; confirm the manual procedure and turnaround]

13. Security

Data moves over encrypted connections. Our database enforces row-level access rules, and deal records can only be reached through our server, never directly by a signed-in browser. Only our team has admin access. Sign-in links and codes are single-use and expire, and hotel request links can be revoked (lifetimes are in section 7). Contract files sit in a private storage bucket. Public forms are rate-limited to slow down abuse. No system is perfectly secure, so we can’t promise absolute security. If we learn of a breach affecting your data, we will tell you [BREACH NOTIFICATION — commitment and timing to confirm with counsel].

14. Children

StayLane is intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact hello@staylaneblocks.com and we will delete it.

15. Where your data lives

StayLane is built for events in the United States, and we operate from the United States. Our email provider is in the US, and our database and hosting are with US-based providers [DATA REGION — confirm the Supabase and Railway regions]; some providers may process data in other countries where they operate. [EU/UK — if EU or UK users are expected, add transfer language with counsel.]

16. Changes to this policy

We may update this policy from time to time. We will revise the “last updated” date above and, for material changes, take additional steps where required by law.

17. Contact

Questions or requests: hello@staylaneblocks.com ([LEGAL ENTITY — e.g., StayLane, Inc.]). See also our Terms of Service.